Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-09-07 CVE-2017-12217 Improper Input Validation vulnerability in Cisco ASR 5500 Firmware
A vulnerability in the General Packet Radio Service (GPRS) Tunneling Protocol ingress packet handler of Cisco ASR 5500 System Architecture Evolution (SAE) Gateways could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
5.3
2017-09-07 CVE-2017-12213 Improper Authentication vulnerability in Cisco IOS XE
A vulnerability in the dynamic access control list (ACL) feature of Cisco IOS XE Software running on Cisco Catalyst 4000 Series Switches could allow an unauthenticated, adjacent attacker to cause dynamic ACL assignment to fail and the port to fail open.
low complexity
cisco CWE-287
4.3
2017-09-07 CVE-2017-12212 Cross-site Scripting vulnerability in Cisco Unity Connection 10.5(2)
A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web interface of an affected system.
network
low complexity
cisco CWE-79
6.1
2017-09-07 CVE-2017-12211 Unspecified vulnerability in Cisco IOS and IOS XE
A vulnerability in the IPv6 Simple Network Management Protocol (SNMP) code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause high CPU usage or a reload of the device.
network
high complexity
cisco
5.3
2017-09-07 CVE-2015-8079 Information Exposure vulnerability in QT Qtwebkit
qt5-qtwebkit before 5.4 records private browsing URLs to its favicon database, WebpageIcons.db.
network
low complexity
qt CWE-200
5.3
2017-09-07 CVE-2015-7672 Cross-site Scripting vulnerability in Centreon 2.6.1
Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27).
network
low complexity
centreon CWE-79
5.4
2017-09-07 CVE-2015-5060 Cross-site Scripting vulnerability in Anchorcms Anchor CMS
Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.
network
low complexity
anchorcms CWE-79
6.1
2017-09-07 CVE-2015-4721 Cross-site Scripting vulnerability in Concretecms Concrete CMS 5.7.3.1
Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1.
network
low complexity
concretecms CWE-79
6.1
2017-09-07 CVE-2015-3169 Cross-site Scripting vulnerability in Askbot 0.7.51
Cross-site scripting (XSS) vulnerability in askbot 0.7.51-4.el6.noarch.
network
low complexity
askbot CWE-79
6.1
2017-09-07 CVE-2017-14195 Cross-site Scripting vulnerability in Finecms Project Finecms 5.0.11
The call_msg function in controllers/Form.php in dayrui FineCms 5.0.11 might have XSS related to the Referer HTTP header with Internet Explorer.
network
low complexity
finecms-project CWE-79
6.1